package controler;

import java.io.IOException;
import java.sql.Connection;
import java.sql.SQLException;
import java.sql.Statement;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import model.SanphamModel;

import dao.GetCnn;
import dao.common;

/**
 * Servlet implementation class RatingSave
 */
@WebServlet("/RatingSave")
public class RatingSave extends HttpServlet {
	private static final long serialVersionUID = 1L;
       
    /**
     * @see HttpServlet#HttpServlet()
     */
    public RatingSave() {
        super();
        // TODO Auto-generated constructor stub
    }

	/**
	 * @throws SQLException 
	 * @throws IOException 
	 * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse response)
	 */
    protected void processRequest(HttpServletRequest request, HttpServletResponse response) throws SQLException, IOException
    {
    	String masp =request.getParameter("masp");
    	String tenkhachhang = request.getParameter("tenkhachhang");
    	tenkhachhang = new String(tenkhachhang.getBytes("8859_1"),"UTF8");
    	String email = request.getParameter("email");
    	String noidung = request.getParameter("noidung");
    	noidung = new String(noidung.getBytes("8859_1"),"UTF8");
    	Connection cnn = GetCnn.getCnn();
		Statement stat = cnn.createStatement();
		masp = common.replace(masp, "'", "''");
		tenkhachhang = common.replace(tenkhachhang, "'", "''");
		email = common.replace(email, "'", "''");
		noidung = common.replace(noidung, "'", "''");
		
		SanphamModel model = new SanphamModel();
    	
    	int sodong = model.getTotalRows("select * from LOIBINHSANPHAM");
    	sodong ++;
		
		String sSQL = "insert into LOIBINHSANPHAM values('"+sodong+"','"+masp+"',N'"+tenkhachhang+"','"+email+"',N'"+noidung+"',getdate())";
		stat.executeUpdate(sSQL);
		response.sendRedirect("ctsanpham.jsp?masp="+masp);
    }
    
	public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		// TODO Auto-generated method stub
		try {
			processRequest(request,response);
		} catch (SQLException e) {
			// TODO Auto-generated catch block
			e.printStackTrace();
		}
	}

	/**
	 * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		// TODO Auto-generated method stub
		try {
			processRequest(request,response);
		} catch (SQLException e) {
			// TODO Auto-generated catch block
			e.printStackTrace();
		}
	}

}
